Privacy Policy

This policy sets out what Scenehand processes, on whose instructions, for how long, and what you can require of us. It is written to be read by a procurement or security team as well as by a customer.

Effective 2 September 2026 Version 1.0 Contact the privacy team
1

Scope and who we are

Scenehand is a footage-intelligence service. You upload or connect video material; we transcribe it, split it into scenes, tag it and make it searchable, and we answer questions about it with citations back to a scene and a timecode.

This policy applies to the Scenehand web application, the Scenehand desktop application for macOS, the Slack integration, and the scenehand.studio website. It covers both the material you entrust to us and the data we hold about you as a customer.

The controller for the purposes of this policy is Scenehand, contactable as set out in clause 16. Where a signed service agreement or data processing agreement is in place, the parties and notice provisions in that agreement take precedence over this clause.

This policy sits alongside, and does not narrow, the data-protection rights you already hold where you are: where UK GDPR, the EU GDPR or another regime applies to you, we apply it, and where two of them would give you different protection, we apply the stronger.

2

Definitions

These are the terms the product itself uses, and they carry the same meaning here.

Footage
Video and audio material you upload or connect, including its embedded metadata and timecode.
Workspace
The private account boundary your projects and members sit inside. Nothing crosses it.
Analysis data
Everything derived from footage: transcripts, speaker labels, scenes, tags, embeddings and story notes.
Proxy
A compressed copy generated for playback and analysis. In browser upload, only the proxy is transmitted.
Customer content
Footage, analysis data, comments, tag libraries and anything else you or your members put into a project.
Credit
The billing unit: one hour of Standard analysis. Consumption is metered per workspace.
3

What we process

3.1
Account and identity data

Name, work email address, your role in the workspace, authentication records and session data. Where your organisation signs in with Google, Microsoft or SSO, we receive an identifier and the profile fields that provider releases; we do not receive or store your password.

3.2
Customer content

The footage you upload or connect, and everything you create around it: comments, tags, project names and member lists. Footage frequently contains personal data — faces, voices, names spoken aloud, locations. You decide what enters a project; we process it on your instructions only.

3.3
Analysis data

Transcripts, speaker labels, scene boundaries, shot attributes, detected objects, embeddings and story notes. This is derived from your footage, is treated as customer content throughout, and is deleted with it.

3.4
Usage and technical data

Credit consumption, processing job records, ingest and error logs, application version, operating system and IP address. We use this to run the service, meter billing accurately, and diagnose failures you report.

3.5
Billing data

Plan, seat count, billing address, invoices and payment status. Card details are entered with our payment processor and are never transmitted to or stored by Scenehand.

3.6
What we do not collect

We do not buy data about you, we do not run advertising or third-party ad trackers, and we do not build profiles of individuals appearing in your footage beyond the speaker and appearance labels that make a project searchable to its own team.

4

Controller and processor roles

The distinction matters, because it determines who answers to the people in your footage.

You are the controller of customer content

You decide what footage is captured, what consents or releases stand behind it, who may see it and how long it is kept. Scenehand acts as your processor and follows your instructions, expressed through the product and through any data processing agreement between us.

We are the controller of account, usage and billing data

For the data described in clauses 3.1, 3.4 and 3.5 we determine the purposes ourselves — running the service, metering it, securing it and invoicing it — and the legal bases in clause 5 apply.

5

Purposes and legal bases

Where we act as controller, we rely on the following.

PurposeBasis
Providing the service — ingest, analysis, search, Ask, StoryPerformance of a contract
Metering credits and issuing invoicesPerformance of a contract; legal obligation
Securing the service, preventing abuse, investigating incidentsLegitimate interests
Diagnosing a fault you have reported to supportPerformance of a contract; legitimate interests
Product and service emails about your workspacePerformance of a contract
Marketing email to prospects who asked for itConsent, withdrawable at any time
6

AI processing and training

Analysis is the product, so this clause is the one most customers turn to first.

  • Your footage is not used to train models. Not ours, not a third party's. There is no setting that opts you in, because there is no mechanism to opt into.
  • Analysis stays inside your workspace. Transcripts, tags and embeddings are scoped to the project they came from. Nothing learned from one customer's footage improves, informs or leaks into another's results.
  • Answers are grounded, not generated from memory. Ask and Story answer only from evidence in your own project and cite a scene and timecode for every claim. Where the footage cannot support an answer, the product says so rather than inventing one.
  • No automated decisions about people. Nothing in Scenehand produces a legal or similarly significant decision about an individual. Speaker and appearance labels exist to make a project searchable by its own team, and are editable by that team.
  • AI proposes; a person approves. Where the product suggests a change — a tag, an in/out range, a jump — it is applied only when a member accepts it.

Transcription and inference run on managed model APIs. We engage a provider only where its terms forbid training on the data we send and forbid retaining it beyond the processing call — a condition of engagement, not a preference. The provider in use, and its processing location, are named in the sub-processor list issued with the data processing agreement in clause 12; they are not fixed here because a provider may be replaced on notice under clause 7.

7

Sub-processors

We engage a deliberately short list, and only where a function cannot sensibly be run in-house. Each is bound by written terms no less protective than this policy.

ProviderFunction and data reached
StripePayments, subscriptions and credit metering. Receives billing data; never receives footage or analysis data.
Microsoft AzureStorage, where you connect your own Azure Blob container. The container remains yours; we read from it under the access you grant and can be cut off by revoking it.
Zitadel (self-hosted)Authentication and SSO, run on our own infrastructure. Because it is self-hosted, identity data is not disclosed to a third-party identity provider.
Infrastructure and model APIsCloud hosting and compute, the transcription and inference APIs, error monitoring, and email and SMS delivery. Each is named, with its processing location, in the sub-processor list issued with the data processing agreement in clause 12, and any change is notified under the terms below. Ask for the list before you upload anything if a specific provider would be a problem for you.

We will give notice of a new or replacement sub-processor before it begins processing customer content, and customers under a data processing agreement may object on reasonable data-protection grounds.

8

Hosting and international transfers

Footage and analysis data are hosted in a single cloud region. That region is stated in your service agreement and confirmed on request before you upload anything — ask first if you have a residency requirement, because customer-selectable regions are not offered yet. Enterprise customers can instead run Scenehand on their own infrastructure, or connect their own storage container, so that material never leaves an estate they control.

Where personal data is transferred outside its region of origin, that transfer relies on the European Commission's standard contractual clauses, or the UK International Data Transfer Agreement where UK law applies to you. Both form part of the data processing agreement in clause 12, and we will provide the version relied on for your workspace on request.

9

Security measures

These are the controls in place today. We would rather understate them than have a procurement team discover the gap themselves.

EncryptionData is encrypted in transit with TLS and at rest in storage.
Workspace isolationEvery request is authorised server-side against the workspace, not merely hidden in the interface. A request that reaches across accounts returns a non-disclosing 404 rather than revealing that a resource exists.
Access controlRoles are Manager, Editor and Viewer; only Managers reach members and billing. At least one Manager must always remain on a workspace. Enterprise workspaces can enforce SSO via OIDC or SAML, and two-factor authentication is available on all plans.
Minimising what we holdIn browser upload, footage is compressed locally and only the proxy is transmitted — your original never leaves your machine. Files that cannot be handled locally are refused with a reason rather than uploaded speculatively.
IntegrityEach original carries a path-free fingerprint, so a rename, a re-encode or a move cannot silently substitute one file for another.
Staff accessScenehand personnel do not browse customer footage. Access to a workspace for support purposes is limited to what is needed to resolve a reported fault, and is logged.
CertificationsWe do not currently hold SOC 2 or ISO 27001 certification, and we do not claim to. If your procurement process requires an attestation, tell us what you need and we will tell you honestly whether and when we can meet it.

If a personal-data breach affects your content, we will notify you without undue delay, with what we know, what we are doing and what we recommend you do — and we would rather tell you early and revise than tell you late and complete.

10

Retention and deletion

DataKept for
Footage and analysis dataAs long as the project exists. Deleting a project removes its media, transcripts, scenes, tags and comments immediately.
A deleted accountDeactivated at once, then a 30-day cancellation window in which you can restore it yourself. At the end of the 30 days the account, its projects, media and analysis are purged permanently.
Invoices and billing recordsAs long as tax and accounting law requires, after which they are deleted.
BackupsNo more than 35 days, on a rolling cycle. Content you delete persists in backups until the cycle completes, and we do not restore a backup to recover content a customer has deleted.
Access and error logsNo more than 12 months, and deleted sooner once they are no longer needed for security or diagnosis. Logs record requests and failures, not the content of your footage.

There is no separate archive of your material, and nothing is held back for training. Cancelling a plan does not delete your library: it stops future charges and leaves the workspace readable to the end of the paid period.

11

Your rights

Subject to the law that applies to you, you may request access to your personal data, correction of it, erasure, a portable copy, restriction of processing, or object to processing we base on legitimate interests. Where we rely on consent, you may withdraw it at any time.

Much of this you can exercise yourself, without asking us: correct a speaker name, delete a project, export a transcript, remove a member, or delete the whole account from Settings. For anything else, write to us at the address in clause 16. We will respond within one month and will not charge you for a first request.

If you appear in footage held by one of our customers and want it corrected or removed, the customer is the controller of that material and the right route is to them. Tell us and we will pass the request on and support them in acting on it, but we cannot alter another organisation's content on our own initiative.

12

Data processing agreements

A data processing agreement is available for Enterprise customers, covering our processor obligations, the sub-processor list, transfer mechanisms, breach notification and audit rights. On-premise deployment and enforced SSO are available on the same plan, for organisations whose footage cannot sit with a vendor at all.

Need paperwork before a shoot?

Ask for the DPA and the current sub-processor list together — they are maintained as one document. Talk to sales →

13

Cookies and local storage

Scenehand uses strictly necessary cookies to keep you signed in and to keep a session attached to the right workspace. The application also uses your browser's local storage to remember interface state — the theme, panel positions, a draft comment you have not sent yet, and which help answers you marked useful.

There is no analytics script on this site or in the application, so there are no analytics cookies, no advertising cookies and no third-party ad trackers to disclose. The only cookies we set are the session and workspace cookies described above; the interface state is held in your browser's local storage and is never sent to us, so clearing site data removes it. If we ever add an analytics cookie it will be listed here and gated behind a consent you are free to refuse.

14

Children

Scenehand is a professional tool sold to organisations, and accounts are not offered to children. Footage may of course contain children — a documentary, a school, a hospital — and where it does, the consents and safeguards behind that material are the responsibility of the customer who captured it. We recommend you record those consents alongside the project.

15

Changes to this policy

We will post a revised version here with a new effective date and version number. Where a change materially affects how we handle customer content, we will tell workspace Managers by email before it takes effect, rather than relying on you to notice a date change.

16

Contact and complaints

Privacy and data-subject requests

privacy@scenehand.studio — include the workspace name and, if you are writing about specific material, the project and file.

Everything else

Product and technical questions go to support@scenehand.studio; contracts and DPAs to sales. Replies within one working day, Monday to Friday.

If you are not satisfied with how we have handled a privacy matter, you may complain to your local supervisory authority. We would rather you came to us first, and we will tell you what we can and cannot do.

Send written correspondence to the privacy address above; a postal address is available on request.

Reviewed 2 September 2026 · Scenehand support & product Privacy answers →Request the DPA →